skill-creator
Pass
Audited by Gen Agent Trust Hub on Mar 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses Python's
subprocessmodule to execute theclaudeCLI and local evaluation scripts. This is a core functional requirement for verifying how other skills are triggered and performed. - [EXTERNAL_DOWNLOADS]: The
eval-viewer/viewer.htmlfile references external assets including Google Fonts and the SheetJS library (cdn.sheetjs.com) for rendering spreadsheets in the report. These are well-known services used for UI presentation. - [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it processes untrusted user prompts and subagent outputs during the skill improvement loop. It uses structured XML-like delimiters (e.g.,
<skill_content>,<attempt>) to separate instructions from data during the description optimization process. - Ingestion points:
evals/evals.json,feedback.json, and subagent transcripts. - Boundary markers: Employs explicit XML-style tags and imperative instructions to Claude to focus on intent generalization.
- Capability inventory: Includes file system access (read/write), subprocess execution, and local HTTP server hosting.
- Sanitization: Employs HTML escaping in report generation and validates
SKILL.mdfrontmatter formatting.
Audit Metadata